Getting Data In

REGISTRY QUERY

jip31jip31
Explorer

hi

i try to query a registry key but Nothing is displayed
index="" sourcetype=WinRegistry key_path="\REGISTRY\USER\.\Software\WOW6432Node\Master\ConfigurationCountry\.*
could you bring me help please?

IN INPUT/
[WinRegMon://hkcu_run1]
disabled = 0
hive = \REGISTRY\USER\.\Software\WOW6432Node\Master\ConfigurationCountry\.
proc = .*
type = set|create|delete|rename
index = windows
thanks

0 Karma

jip31jip31
Explorer

it works until :
index="" sourcetype="winregistry" key_path="\registry\user
but after un have an error message:
⚠ Events may not be returned in sub-second order due to search memory limits configured in limits.conf:[search]:max_rawsize_perchunk. See search.log for more information.

0 Karma

logloganathan
Motivator

Could you please share the search.log information

0 Karma

jip31jip31
Explorer

BUTut i got results Index="windows" sourcetype=WinRegistry

0 Karma

p_gurav
Champion

After getting above data can you select the key_path from selected fields? Also can you try to find out Event Code 4657 ?

This doc may help:
https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/5a3187b4419202f0fb8b2dd1/151319544...

0 Karma

jip31jip31
Explorer

hI loglognathan Nothing is also displayed....

0 Karma

logloganathan
Motivator

Could you please try this query

index="windows" sourcetype=WinRegistry disabled = 0 type=set OR type=create OR type=delete OR type=rename key_path="\REGISTRY\USER.\Software\WOW6432Node\Master\ConfigurationCountry.*

0 Karma

jip31jip31
Explorer

hi

now i use this request but Nothing is displayed.
index="" sourcetype=WinRegistry disabled = 0 type=set OR type=create OR type=delete OR type=rename key_path="\REGISTRY\USER.\Software\WOW6432Node\Airbus\Master\ConfigurationCountry."
an idea please?

0 Karma

logloganathan
Motivator

Could you please try only this query
ndex="windows" sourcetype=WinRegistry disabled = 0 type=set OR type=create OR type=delete OR type=rename

0 Karma

logloganathan
Motivator

Could you please provide the SS of Index="windows" sourcetype=WinRegistry

or please provide the result sample

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...